If your PC is ever locked by ransomware, paying up won't necessarily release your files; in fact, we recommend that you never hand over cash to these scammers.
What to do? There's a minor chance you can save your files without surrendering your wallet or trashing your PC entirely. A group of security researchers routinely examines the latest ransomware strains for flaws in their computer code, and develops free tools that can (sometimes) reverse the infection.
Michael Gillespie is among those researchers. He's a programmer by day, but in his free time he works as a ransomware hunter for the New Zealand-based antivirus firm Emsisoft, a leading provider of ransomware decryptors. Desperate victims frequently reach out to him for help. "I can get anywhere from 50 to 200 people contacting me per day. It's crazy," he said in an interview.
When a ransomware infection hits your PC, the malicious code encrypts your files and posts a note, demanding you pay up or never see your data again. If you give in, the hackers will (theoretically) send you a decryption key to recover your files. But like any piece of software, a ransomware strain can be buggy. Gillespie has exploited those vulnerabilities to create an estimated 100 decryptors, which anyone can download for free.
The bugs can happen for a number reason: The hacker behind the malicious code may be a newbie. Or the ransomware itself may be an early first version, and has yet to work out all its kinks. If there's a weakness in the encryption algorithmthe crucial process that will turn your files into gibberishthen a researcher can potentially unravel a ransomware attack and reverse the infection.
(Gillespie has a YouTube channel devoted to ransomware decryption.)
"The golden rule is that crypto (cryptography) is hard, and ransomware developers are human too," Gillespie said. Lately, victims have been reaching out to him for help to recover from the "STOP DJVU" strain, which often comes packaged with pirated software. Fortunately, Gillespie was able to create a decryptor since early versions of the attack embeded a usable decryption key to reverse the infection within the ransomware's computer code.
"Ransomware authors, as a whole, really don't learn," said Fabian Wosar, chief technology officer at Emsisoft. Wosar began hunting ransomware in 2012, and since then, he's created decryptors for an estimated 150 ransomware families or more, which he finds surprising.
(Emsisoft's decryption tool list)
"Four years ago, I was 100 percent sure that by now we would never see a ransomware family again that had any flaws that we could exploit," he said. "But we still see them at the same frequency."
He suspects the biggest reason why is because rookie hackers are routinely trying their hand at ransomware. "A whole bunch of new people are joining the game," he said. The more successful ransomware authors, on the other hand, can retire after raking in so many ransoms. "So we have a whole bunch of new people committing the same mistakes again and again."
Wosar estimates there's usually a one-in-five chance a brand-new ransomware strain can be successfully decrypted. Other strains have been reversed thanks to law enforcement agencies busting the hackers and retrieving decryption keys from their servers.
But many hackers behind the biggest ransomware attacks appear to be pros who continue to elude capture. Today's most notorious ransomware strainssuch as REvil and Ryukare likely linked to organized cybercriminal gangs that specialize in targeting businesses and city governments and have successfully extorted millions in bitcoin from victims.
(Ron Engelaar/AFP/Getty Images)
Researchers such as Wosar and Gillespie have made a major dent in some of the hackers' earnings, with their individual decryptors downloaded tens of thousands of times.
So why are these researchers helping victims for free? It's not exactly sound economics for an antivirus firm to create a decryptor at no cost. But it does generate good press for Emsisoft, which helps justify the time and effort.
"I feel like I'm doing my good part in the world, and getting my fame in," Gillespie said. Fascinated by cryptography, he began tackling ransomware over four years ago as a hobby.
As for Wosar: "Personally, my biggest reason why I'm doing this is I really enjoy pissing off the ransomware authors."
Still, foiling hackers can sometimes come at a price. Last year, Wosar left his home country of Germany over worries a ransomware author might one day try to track him down and send a hired killer. "At this point, we may have done $750 million in damages to all the different hacking groups," he estimated. "It would only take a tiny fraction of that amount to send someone to visit me, and convince me not to write decryptors anymore."
(Messages ransomware authors have left for Fabian Wosar over the years.)
Wosar says he's currently "laying low" in the UK, where he continues to examine and decrypt the latest ransomware strains. He also keeps a digital folder with screenshots of all the times hackers have insulted him for decrypting their ransomware attacks. In 2016, one cybercriminal even created a malware strain named "Fabiansomware" to troll Wosar.
"It's like flattery, almost," Wosar said.
Emsisoft isn't alone in developing ransomware decryptors. The industry, along with law enforcement, created Nomoreransom.org, which hosts various free decryptors, and has helped more than 200,000 victims recover from attacks, according to Europol.
US law enforcement is not part of the Nomoreransom.org project, though, likely because the website's partners include Russian antivirus firm Kaspersky Lab and the Russian Ministry of Internal Affairs.
An FBI spokesperson told us the agency's main role is with ransomware investigations, which can include privately consulting with victims on their recovery options. "We'll point people to decryption keys that are publicly available, and tell them to use their best judgment," the spokesperson added.
(The Nomoreransom.org site.)
Although the free decryption tools can provide some relief to the ongoing ransomware epidemic, they have their limits. That's because ransomware authors can be quick to fix their creations.
"Whenever you release a free decryption tool, you are telling the bad guys to tweak their code," said Jakub Kroustek, a security researcher at antivirus firm Avast, who also develops decryption tools. "If the hackers are clever enough, they will fix it."
"There are two sides of this coin," he added. "If a new ransomware strain arrives, and you're the first victim, the chances are quite good there's some flaw." But those decryption tools can also help hackers refine and debug their attacks, making their ransomware creations resistant to future attempts at decryption.
As a result, it'll take more than finding software bugs to stop the ongoing ransomware epidemic. Victimsincluding consumers, businesses, and governmentswill need to stop giving into the ransomware demands, and focus on protecting their computers.
"The number one prevention tip is backups," Gillespie said. "If all your safety nets fail, a backup is what can save your ass in the end."
Read more from the original source:
These Researchers Want to Save You From Ransomware (for Free) - PCMag
- This Is My New Golden Rule for Renting Vacation Homes (I Was Doing It All Wrong) - Yahoo Life - April 12th, 2024 [April 12th, 2024]
- Misguided culture warriors should heed the golden rule [column] - LNP | LancasterOnline - April 12th, 2024 [April 12th, 2024]
- Michael L. Fischler: Anger and The Golden Rule - The Union Leader - April 10th, 2024 [April 10th, 2024]
- Dog trainer reveals her golden rule for recall training (we can't believe how simple it is!) - Yahoo Life - April 10th, 2024 [April 10th, 2024]
- Fr. Aristides Palaynes and the Golden Rule Community - Greek Orthodox Archdiocese of America - Greek Orthodox Archdiocese of America - April 10th, 2024 [April 10th, 2024]
- How Lulu still looks fabulous at 75, from her skincare 'golden rule' to refusing to take lifts - as star revea - Daily Mail - April 10th, 2024 [April 10th, 2024]
- Ken Henry: We are breaking the 'golden rule' of economic policy - ABC News - April 10th, 2024 [April 10th, 2024]
- The Golden Rule and the Free Market - Foundation for Economic Education - March 6th, 2024 [March 6th, 2024]
- Courtney B. Vance and Angela Bassett share their golden rule for successful parenting - The Times of India - March 6th, 2024 [March 6th, 2024]
- Live music at The Golden Rule Coffee House on Friday, March 8 - Redwood Falls Gazette - February 29th, 2024 [February 29th, 2024]
- Blake Lively and Ryan Reynolds have always followed one relationship rule - Marie Claire UK - February 29th, 2024 [February 29th, 2024]
- The Golden Rule - A Way of Life - County 10 News - January 27th, 2024 [January 27th, 2024]
- Dear Annie: Nurses Golden Rule might be the answer to relationship problems - MLive.com - January 27th, 2024 [January 27th, 2024]
- Aitana's golden rule and the pending account she has with her most loyal audience - WECB - January 27th, 2024 [January 27th, 2024]
- Guest columnist David Hernndez: Climate, refugees, and the golden rule - GazetteNET - January 27th, 2024 [January 27th, 2024]
- A golden rule that should have been followed in North - The Sun Chronicle - January 27th, 2024 [January 27th, 2024]
- The Golden Rule Refined | | news-journal.com - Longview News-Journal - January 27th, 2024 [January 27th, 2024]
- Film About The Golden Rule Released in Bali - EIN News - January 27th, 2024 [January 27th, 2024]
- Heres a Golden Rule Jeff Bezos Seems to Have Forgotten: Never Let Your Ego Get in the Way of Doing Business - The Good Men Project - January 27th, 2024 [January 27th, 2024]
- Universalists to consider the mandate of the Golden Rule - Ashland Daily Press - November 20th, 2023 [November 20th, 2023]
- 6-Year-Old Boy Dies a Month After Adult Neighbor Allegedly Beats ... - PEOPLE - November 20th, 2023 [November 20th, 2023]
- COLUMN: Celebrate Thanksgiving year-round with 'Thanks-living ... - Andalusia Star-News - November 20th, 2023 [November 20th, 2023]
- Silence is craven, not golden - The Gazette - November 20th, 2023 [November 20th, 2023]
- Sellars CEO Named to Wisconsin 'Titan 100' - Industrial Distribution - November 20th, 2023 [November 20th, 2023]
- The most valuable decluttering lessons I have learned | - Homes & Gardens - November 20th, 2023 [November 20th, 2023]
- COMMENTARY| Bethel: Too much hate | Opinion ... - Bennington Banner - November 20th, 2023 [November 20th, 2023]
- Cooking with Love Nello's Continues Impress Diners - St. Albert Gazette - November 20th, 2023 [November 20th, 2023]
- What Happened to James Garner? Inside the 'Maverick' Star's ... - Yahoo Entertainment - November 20th, 2023 [November 20th, 2023]
- Successful trial of coating that converts UV into PAR boosts sales - hortidaily.com - November 20th, 2023 [November 20th, 2023]
- Debt rules will affect the most vulnerable, EU trade union chief warns - EURACTIV - November 20th, 2023 [November 20th, 2023]
- Guest Opinion | Bill Paparian: Pasadena City Hall Believes in the ... - Pasadena Now - May 18th, 2023 [May 18th, 2023]
- Golden ratio in venation patterns of dragonfly wings | Scientific Reports - Nature.com - May 18th, 2023 [May 18th, 2023]
- The Golden Rule Of Data Gathering And New Expectations Of Value ... - The Drum - May 18th, 2023 [May 18th, 2023]
- Glass gets away with breaking the golden rule - The Irish News - May 18th, 2023 [May 18th, 2023]
- Red Horse Recruiter Ranks First in Class - 125fw.ang.af.mil - May 18th, 2023 [May 18th, 2023]
- These 19 Birmingham BBQ joints are the ultimate Memorial Day ... - Bham Now - May 18th, 2023 [May 18th, 2023]
- Mountain West Technologies wins Casper Area Chamber of ... - Cap City News - May 18th, 2023 [May 18th, 2023]
- The Unseen Engine of South Florida's Booming Vacation Rental Market: Estaga - Yahoo Finance - May 18th, 2023 [May 18th, 2023]
- Simon Cowell to break important BGT rule this weekend, ITV confirms - South Wales Argus - May 18th, 2023 [May 18th, 2023]
- Starting out on the St. Croix: What High School Skiing Taught Jessie ... - fasterskier.com - May 18th, 2023 [May 18th, 2023]
- These are the weirdest and least understood pickleball rules and ... - msnNOW - May 18th, 2023 [May 18th, 2023]
- Media Source Not Showing in OBS? Here's How to Fix It - MUO - MakeUseOf - May 18th, 2023 [May 18th, 2023]
- Youngkin avoids talk of diversity, politics at VMI graduation - Cardinal News - May 18th, 2023 [May 18th, 2023]
- Mother's Day roots: the opposition to war | READER COMMENTARY - Baltimore Sun - May 18th, 2023 [May 18th, 2023]
- Rep. Gallagher says US needs to take off 'golden blindfolds' and 'open our eyes' to China risk - Fox News - May 18th, 2023 [May 18th, 2023]
- Open Heaven 18 May 2023: The Gift of Love - ELANHUB MEDIA - May 18th, 2023 [May 18th, 2023]
- 10 Best Quotes About Family In The Fast & Furious Franchise - CBR - Comic Book Resources - May 18th, 2023 [May 18th, 2023]
- Life in the Fast Lane - New DOE Rule Changes Push LNG Projects ... - RBN Energy - May 18th, 2023 [May 18th, 2023]
- Dont Say That Word- Days After Golden Advice From Wrexhams Ryan Reynolds, NFL Icon JJ Watt Reminds Wife of Unspoken Rule After Burnley Investment -... - May 18th, 2023 [May 18th, 2023]
- 14 Handy Tricks To Get Better Sleep While Backpacking - The Trek - May 18th, 2023 [May 18th, 2023]
- Investors overlooking the golden rule as they flock to DIY apps - Stuff - April 29th, 2023 [April 29th, 2023]
- 7 money 'rules' you can actually break, according to financial experts - MarketWatch - April 29th, 2023 [April 29th, 2023]
- Dorsman: MP Motorsport betting on caution ahead of inevitable ... - Formula 2 - April 29th, 2023 [April 29th, 2023]
- Boomer explains why millennials are having a hard time at work: 'It's ... - Upworthy - April 29th, 2023 [April 29th, 2023]
- AFA.net - Basic Fairness in Women's Sports - American Family Association - April 29th, 2023 [April 29th, 2023]
- How To Prep Air Fryer Vegetables So They Don't Escape The Basket - Tasting Table - April 29th, 2023 [April 29th, 2023]
- Pansexual Flag: Here's what the Pride Flag's colors mean and more - USA TODAY - April 29th, 2023 [April 29th, 2023]
- What is the "Rules-Based-Order"? - CounterPunch.org - CounterPunch - April 29th, 2023 [April 29th, 2023]
- Hudson WWII vet turns 100, decides to quit the bocce ball team - Suncoast News - April 29th, 2023 [April 29th, 2023]
- Kansas City reportedly let Meta developer break diversity rules, then ... - KCUR - April 29th, 2023 [April 29th, 2023]
- From the Right: Drawing the line between trans rights and parental ... - The Malibu Times - April 29th, 2023 [April 29th, 2023]
- I was 40,000 in debt but got myself out of it here is the rule I swear by and how it changed my life... - The Sun - April 29th, 2023 [April 29th, 2023]
- OBITUARY - Mary Anderson - Berthoud Weekly SurveyorBerthoud ... - BerthoudSurveyor.com - April 29th, 2023 [April 29th, 2023]
- 8 ways to improve your written communications - Smartbrief - April 29th, 2023 [April 29th, 2023]
- Draymond Green: Draymond wont be moved by the Draymond rule - Eurohoops - April 29th, 2023 [April 29th, 2023]
- Dont Make These 4 Nursing Home Abuse Claim Mistakes in Las ... - Legal Reader - April 29th, 2023 [April 29th, 2023]
- What Food to Pack for Family Hikes - Outside - April 29th, 2023 [April 29th, 2023]
- Lawyer Discernment Is Critical In The World Of AI - JD Supra - April 29th, 2023 [April 29th, 2023]
- 12 blockbuster movies for summer 2023 ranked: we can't wait! - What To Watch - April 29th, 2023 [April 29th, 2023]
- Meghan broke 'golden rule' months before royal exit and has done so ever since - Express - April 20th, 2023 [April 20th, 2023]
- We Are All Connected: Loving One Another in Different Religions - Graphic - April 20th, 2023 [April 20th, 2023]
- Grammar Girl AP style tips on the Oxford comma, headlines and more - PR Daily - April 20th, 2023 [April 20th, 2023]
- How to prevent HVAC havoc this summer - KCAU 9 - April 20th, 2023 [April 20th, 2023]
- Take the right care of your yard | News | hometownnewsbrevard.com - Hometown News - April 20th, 2023 [April 20th, 2023]
- Britain's Got Talent: Simon Cowell speaks out after new judge Bruno Tonioli breaks rule on first appearance - LADbible - April 20th, 2023 [April 20th, 2023]
- After experimenting with directives, ISSF reinstates the Tokyo Olympics old-golden rule book for Paris 2024 - Free Press Journal - April 20th, 2023 [April 20th, 2023]
- Want to stay married? Gogglebox's Steph and Dom reveal golden ... - Daily Mail - April 20th, 2023 [April 20th, 2023]
- Overcoming Spiritual Violence and Embracing Peace with Rev. Dr ... - Bear World Magazine - April 20th, 2023 [April 20th, 2023]
- Good News, Part 3 of Resurrection as the Good News | Good News ... - Patheos - April 20th, 2023 [April 20th, 2023]
- What to Do After an Auto Accident: A Step-by-Step Guide - BBN Times - April 20th, 2023 [April 20th, 2023]